Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,777
Quick preset (or use dates below)
Clear Filters
Showing 6,441 - 6,460 of 13,907 CVEs
CVE-2026-32081 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32079 MEDIUM - 5.5

Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an authorized attacker to disclose information locally.

Vendor: microsoft
Product: windows_10_1607
Published: Apr 14, 2026
Source: NVD
CVE-2026-32072 MEDIUM - 6.2

Improper authentication in Windows Active Directory allows an unauthorized attacker to perform spoofing locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-27931 MEDIUM - 5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-27930 MEDIUM - 5.5

Out-of-bounds read in Windows GDI allows an unauthorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-27925 MEDIUM - 6.5

Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to disclose information over an adjacent network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-27906 MEDIUM - 4.4

Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-27288 MEDIUM - 5.4

Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of...

Vendor: Adobe
Product: Adobe Experience Manager
Published: Apr 14, 2026
Source: NVD
CVE-2026-27258 MEDIUM - 5.5

DNG SDK versions 1.7.1 2502 and earlier are affected by an out-of-bounds write vulnerability that could lead to application denial-of-service. An attacker could leverage this vulnerability to corrupt memory, causing the application to crash or become unresponsive. Exploitation of this issue requires...

Vendor: Adobe
Product: DNG SDK
Published: Apr 14, 2026
Source: NVD
CVE-2026-26175 MEDIUM - 4.6

Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26169 MEDIUM - 6.1

Buffer over-read in Windows Kernel Memory allows an authorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-26155 MEDIUM - 6.5

Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

Published: Apr 14, 2026
Source: NVD
CVE-2026-24907 MEDIUM - 5.4

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a stored cross-site scripting (XSS) vulnerability in the Event Log mail preview feature. When viewing logged mail messages, HTML content was rendered in an iframe without proper sandboxing, all...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-24906 MEDIUM - 5.4

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline styles, table styles, etc.) did not sanitize input...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-23670 MEDIUM - 5.7

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23653 MEDIUM - 5.7

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-21331 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-20945 MEDIUM - 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20928 MEDIUM - 4.6

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20806 MEDIUM - 5.5

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD